{"id":"GHSA-jpvm-9frm-hjcq","summary":"Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode","details":"A vulnerability in Nuclei's DAST/fuzz expression evaluation path allows a malicious target server to trigger disclosure of scanner-host environment variables when the `-env-vars` / `-ev` option is explicitly enabled.\n\nThis is an incomplete fix for [CVE-2026-41645](https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jm34-66cf-qpvr) / GHSA-jm34-66cf-qpvr. The original fix hardened `expressions.Evaluate()` to be single-pass within one call, but did not address callers that invoked evaluation multiple times on substituted output in the DAST/fuzz pipeline.\n\n**Affected Component**\n\nThe issue is in the DAST/fuzz payload evaluation path (`pkg/fuzz/parts.go`) and the shared template rendering boundary. When a multi-step template captures response data via an internal extractor and reuses it in a subsequent fuzz step, the fuzz evaluator could treat the substituted response content as fresh template syntax on a second evaluation pass.\n\n**Description**\n\nIn DAST/fuzz mode, payload evaluation previously ran expression substitution more than once on the same value. Response-derived content captured by an `internal: true` extractor in a prior protocol step could flow into a fuzz payload and be reinterpreted as DSL/helper syntax on a subsequent pass.\n\nWhen `-env-vars` (`-ev`) is enabled, environment variables are merged into the template variable map. A malicious target can return response data containing expressions like `{{env_var_name}}` which, when reused in a subsequent fuzz step, resolve to actual environment variable values. This can expose sensitive host data such as API keys, credentials, and tokens.\n\nWithout `-ev` enabled (the default), response-derived data may still cause other DSL helpers to run, but that behavior is not treated as a security issue and has no meaningful security impact beyond unexpected behavior.\n\n\u003e [!NOTE]\nThe `-env-vars` / `-ev` option is off by default. Users who have not explicitly enabled it are not affected by this vulnerability.\n\n**Affected Users**\n\n- **CLI users** running `nuclei -dast` (or fuzzing) with multi-step templates that chain an internal extractor into a subsequent fuzz step against untrusted targets, with the `-ev` flag enabled.\n- **SDK users** who integrate Nuclei with the fuzz pipeline enabled, `EnvironmentVariables` set to `true`, and scan targets that are not fully trusted.\n\n**Patches**\n\n- The vulnerability is fixed in Nuclei v3.10.0. Upgrading is strongly recommended.\n- Fix reference: https://github.com/projectdiscovery/nuclei/pull/7499\n- Related original fix: https://github.com/projectdiscovery/nuclei/pull/7221, https://github.com/projectdiscovery/nuclei/pull/7321\n\n**Mitigation**\n\nUpgrade to Nuclei v3.10.0, where template-authored text is rendered once through a shared rendering boundary and runtime values from responses, extractors, and constants remain opaque data.\n\nIf you have `-ev` enabled, disable it when scanning untrusted targets to avoid environment variable disclosure.\n\n**Workarounds**\n\nIf upgrading is not an option, ensure `-env-vars` / `-ev` is not enabled when running DAST/fuzz scans with multi-step templates against untrusted targets.\n\n**Acknowledgments**\n\nThanks to @BerSecHub for reporting this issue.","aliases":["CVE-2026-76805"],"modified":"2026-09-22T21:00:10.599215076Z","published":"2026-09-22T20:37:24Z","database_specific":{"cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-22T20:37:24Z","nvd_published_at":"2026-09-22T17:17:25Z"},"references":[{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-jpvm-9frm-hjcq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76805"},{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/pull/7499"},{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/commit/ccbfb12bd01447ba25f6e755dfb2bee677736da6"},{"type":"PACKAGE","url":"https://github.com/projectdiscovery/nuclei"},{"type":"WEB","url":"https://github.com/projectdiscovery/nuclei/releases/tag/v3.10.0"}],"affected":[{"package":{"name":"github.com/projectdiscovery/nuclei/v3","ecosystem":"Go","purl":"pkg:golang/github.com/projectdiscovery/nuclei/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.10.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-jpvm-9frm-hjcq/GHSA-jpvm-9frm-hjcq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}